Impact
The vulnerability in IBM DataStage on Cloud Pak for Data 5.4.0.0 arises from improper neutralization of special elements used in an OS command. A remote authenticated attacker can craft input that bypasses command sanitization and execute arbitrary commands. This flaw permits full code execution, enabling the attacker to compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
IBM DataStage on Cloud Pak for Data version 5.4.0.0 is affected. The vendor recommends upgrading to patch level 5 or later in the 5.4 series, following IBM's instructions.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting no publicly documented exploits to date. The flaw requires an attacker to be authenticated with a valid user account; once authenticated, the attacker can trigger the vulnerable command path and achieve arbitrary code execution. Therefore, even without public exploits, the high severity and ability for a compromised account to execute code present a significant risk.
OpenCVE Enrichment